Privacy controls
CyberFurl can load analytics only after you opt in. Core product features work without analytics consent.
Perform deep, authoritative DNS nameserver resolution. Trace delegation paths from root servers, inspect glue records, and validate NS configuration against RFC 1034/1035 standards to prevent zone poisoning and resolution failures.
A DNS Nameserver (NS record) is an authoritative server that holds DNS zone records for a domain. NS records delegate authority over a domain to specific servers. Multiple NS records provide redundancy — if one fails, others continue resolving queries.
Incorrect NS delegation — lame servers, mismatched glue records, or single points of failure — causes complete DNS resolution failure. Without proper NS redundancy, your domain becomes unreachable if one server goes offline.
Hosting all NS records on the same subnet (single point of failure), missing in-bailiwick glue records, parent-child NS mismatches, and lame delegations returning SERVFAIL are the most critical NS misconfigurations.
Initiates a recursive trace from the DNS root to retrieve the TLD referral and identify all delegated nameservers.
Queries the TLD nameservers to retrieve the delegated NS records and glue address records for your domain.
Directly queries each delegated nameserver to verify it responds authoritatively and returns consistent zone data.
Cross-references parent zone delegation with child zone NS records to detect mismatches, lame delegations, and missing glue.
Traces the complete DNS resolution path from root servers through TLD to your authoritative nameservers, visualizing each referral step.
Extracts and validates in-bailiwick glue records provided by the parent zone, ensuring nameservers with names inside the zone have correct A/AAAA addresses.
Identifies discrepancies between NS records delegated by the parent TLD and the NS records served by your own authoritative nameservers.
Evaluates nameserver diversity by checking if NS hosts are distributed across different IP subnets and autonomous systems for true fault tolerance.
Automatically flags nameservers that refuse queries or return non-authoritative responses, indicating misconfigured or abandoned delegations.
Checks for the presence and validity of AAAA glue records to ensure your domain resolves correctly over pure IPv6 networks.
Instantly verify your NS delegation, detect lame delegations, and ensure your domain's DNS infrastructure is redundant and fully RFC compliant.